No way, no how.
No way, no how.
When I clicked the "none of these work for me" link at the bottom, I was presented with:
"Sorry, We are unable to log you in.
Your account is temporarily disabled. Accounts may be disabled when you attempt to log in with incorrect information or fail to complete a security challenge."
On the one hand, I'm probably glad the data is shit? But on the other hand, folks consuming the data might not understand that.
In fact, they already hired a music major CISO who leaked all that data in a stunning display of executive incompetence.
https://www.marketwatch.com/story/equifax-ceo-hired-a-music-...
Software security is a mess in large part because of the phenomenon you describe.
That "but she has a music degree!" is the least relevant part of evaluating if someone is qualified for such a CISO role or not. Someone with the "wrong" degree but talent and relevant experience would easily beat someone with a fancy "Masters of Information Security" degree that then muddled around in less relevant areas. Focusing on people's degrees is almost always the wrong measure in IT.
Sure, totally agreed.
> Focusing on people's degrees is almost always the wrong measure in IT.
Maybe 20 years ago. (I was there.)
Today, asking for exceptional technical depth and a proven track-record of leadership is not a big ask.
You're guessing wrong.
> Having a track record is pretty basic when evaluating people for high level positions who have non-traditional backgrounds.
Not sure why you're saying that in a thread where everybody agrees that track record is important?
> Why is this upsetting to you?
It's not upsetting, I just think, as I've explained multiple times, that putting a spotlight on the degree alone, as the linked article does, is a bad argument, given that track record and experience matter much more than what degree someone got years ago. It's a cheap gotcha.
> It's not upsetting
You know what's truly upsetting? Pervasive gross incompetence in the C suites of American companies.
> I just think, as I've explained multiple times, that putting a spotlight on the degree alone, as the linked article does, is a bad argument
Why?
It would be a fucking scandal in literally any other field.
"Chief Medical Officer didn't have any medical training".
"Chief Accounting Officer doesn't have any accounting training and isn't a CPA."
Do you not respect IT as a profession? Or do you think anyone who has read some WebMD, shadowed a bit, and muddled through a few years of physical exams at a family practice should qualify for a CMO position?
> ...given that track record and experience matter much more than what degree someone got years ago. It's a cheap gotcha.
No, it isn't. Insisting on a formal demonstration of knowledge -- in addition to experience -- is not unreasonable.
The IT status quo doesn't exist in any other profession.
Engineers must attend ABET-accredited programs and then become or work under PEs.
Certification and required education is pervasive in medicine.
Lawyers attend law school pass the bar.
CPAs and actuaries take difficult exams.
Fact: IT security is a complete cluster fuck. Incompetence is everywhere. For every competent self-taught person there are dozens of dunning-kruger idiots. The status quo does not work. At all.
There are many jobs in software shouldn't require formal certification of technical knowledge. Just like there are many jobs in medicine, law, accounting, and finance that do not require formal certifications.
CISO of a credit bureau isn't one of those jobs.